Compliance & Registrations
No Sweat Work Media CC
Trading as NoSweat
Registration Number: 2009/090625/23
Website: www.nosweat.co.za
Our Commitment to Compliance
NoSweat is committed to responsible business practices, privacy, information security and compliance with applicable South African legislation, including the Protection of Personal Information Act 4 of 2013 (“POPIA”) and the Promotion of Access to Information Act 2 of 2000 (“PAIA”).
NoSweat maintains a compliance programme designed to support the lawful and responsible processing of personal information belonging to candidates, freelancers, clients, suppliers and other individuals who interact with us.
This page provides an overview of our principal registrations, compliance documentation and governance measures.
NoSweat does not represent that publication of policies or completion of a self-assessment constitutes certification by the Information Regulator.
Information Officer Registration
NoSweat has appointed an Information Officer responsible for overseeing POPIA and PAIA matters.
Information Officer: Sebastian van ’t Hoff
Organisation: No Sweat Work Media CC
Registration Number: 2009/090625/23
Email:sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053
PAIA Annual Reporting
NoSweat submits PAIA reporting information to the Information Regulator where required.
Latest Reporting Period: [INSERT]
Submission Status: [SUBMITTED / PENDING / INSERT APPROPRIATE STATUS]
Submission Date: [INSERT]
PAIA Annual Reporting Confirmation Certificate: [VIEW CERTIFICATE]
The Information Regulator's eServices portal specifically provides a downloadable PAIA Annual Reporting Confirmation Certificate for completed annual reporting submissions. (eServices)
POPIA Compliance Self-Assessment
NoSweat periodically assesses its POPIA compliance using appropriate internal controls and, where applicable, the Information Regulator's POPIA Self-Assessment tool.
The Information Regulator describes its self-assessment as a tool to help organisations evaluate compliance with POPIA's eight conditions and identify areas requiring improvement. The Regulator also makes clear that the checklist is not exhaustive. (eServices)
Accordingly, completion of a POPIA self-assessment should not be interpreted as certification or approval by the Information Regulator.
PAIA Compliance Self-Assessment
NoSweat may similarly conduct periodic assessments of its PAIA compliance.
The Information Regulator's PAIA assessment is also described as a compliance evaluation and improvement tool rather than an exhaustive certification process. (eServices)
Compliance Documentation
NoSweat maintains a range of policies, procedures and records forming part of its privacy and governance framework, including:
Privacy Policy
POPIA & Data Protection
PAIA Manual
Cookie Policy
Information Officer Registration & Contact Details
Record of Processing Activities (ROPA)
Data Breach & Security Compromise Response Plan
Direct Marketing Policy
Do Not Sell or Share My Personal Information
Supplier Code of Conduct
Anti-Slavery & Human Trafficking Policy
These documents are reviewed and updated as our business, technology and legal obligations develop.
POPIA Governance
NoSweat's compliance programme includes measures relating to:
Accountability — responsibility for personal-information governance and oversight.
Processing limitation — personal information should only be processed where there is an appropriate purpose and lawful justification.
Purpose specification — information should be collected for defined and legitimate purposes.
Information quality — reasonable steps are taken to maintain appropriate and accurate information.
Transparency — candidates, clients and other data subjects are informed about relevant processing activities.
Security safeguards — reasonable technical and organisational measures are maintained to protect personal information.
Data-subject participation — individuals are provided mechanisms to exercise applicable POPIA rights.
Verification and Evidence
Where NoSweat publishes an official registration or reporting certificate issued by the Information Regulator, the certificate should be understood according to its stated purpose.
For example, an Information Officer Registration Certificate confirms Information Officer registration. It does not itself certify every aspect of an organisation's POPIA compliance.
Similarly, a PAIA Annual Reporting Confirmation Certificate confirms the relevant reporting submission; it should not be represented as a general POPIA compliance certificate.
The Information Regulator's current eServices portal separates registration, annual reporting, self-assessment, prior authorisation, security-compromise reporting and other compliance functions. (eServices)
Continuous Compliance
Privacy and data protection compliance is an ongoing process rather than a one-time exercise.
NoSweat periodically reviews its:
policies and notices;
processing activities;
Record of Processing Activities;
operators and service providers;
information-security measures;
retention practices;
consent and direct-marketing processes;
data-subject request procedures;
incident-response arrangements; and
relevant regulatory requirements.
Contact the Information Officer
Questions about NoSweat's compliance programme or handling of personal information may be directed to:
No Sweat Work Media CC
Trading as NoSweat
Information Officer: Sebastian van ’t Hoff
Email:sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053
Website:www.nosweat.co.za
